Linux 软件免费装
Banner图

Nivoli Edge

开发者 calimonk
更新时间 2026年9月15日 04:49
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

cache performance security cloudflare image-optimization

下载

1.69.0 1.70.0 1.70.1 1.70.2 1.70.3 1.70.4 1.70.5 1.70.6 1.71.0 1.71.1 1.72.0 1.72.1 1.72.2 1.72.3 1.72.4 1.72.5 1.48.2 1.49.0 1.50.0 1.50.1 1.50.2 1.51.0 1.51.1 1.52.0 1.52.1 1.52.2 1.53.0 1.53.1 1.54.0 1.54.1 1.55.0 1.56.0 1.56.1 1.57.0 1.57.1 1.57.2 1.57.3 1.57.4 1.57.5 1.57.6 1.57.7 1.57.8 1.57.9 1.58.1 1.58.2 1.58.3 1.58.4 1.59.0 1.60.0 1.61.0 1.62.0 1.63.0 1.64.0 1.58.0 1.60.1 1.65.0 1.66.0 1.66.1 1.66.2 1.48.3 1.67.0 1.68.0 1.68.1 1.68.2

详情介绍:

Nivoli Edge is a security layer that lives one step above WordPress. Attacks, floods, scanners and code changes are refused at Cloudflare's edge before a request reaches PHP, and the settings that refuse them live there too, behind an email confirmation, so a hacked WordPress cannot switch them off or install anything. The same edge serves whole HTML pages and right-sized images from the node nearest each visitor, and every number shows up inside WP admin. Free and managed, in one sentence: the plugin is free and GPL and everything that runs on your own server works without an account; the shields, the locks, the edge cache and the numbers need the managed edge, from 15 euro a month with a 14-day trial. The Edge Security layer Wordfence and Sucuri run inside the site they protect. This runs one layer up, at the edge, and the site cannot reach it. Ten shields, refused before PHP. Your server never boots PHP to turn a request away. Eight of them come with every managed plan; the AI-crawler block and the wp-admin IP lock from the Growth plan up. The stray-PHP and surface locks have a monitor mode that lists what blocking would have stopped before it blocks anything. Three locks, nothing inside the site can turn off. A takeover of your WordPress admin owns every plugin's settings page. Ours refuses to act on WordPress's say-so. Evidence: who did what, from where. Underneath all of it, Cloudflare's managed WAF rulesets, including the WordPress rule set, run in front of every managed site. Pages served from the edge Full-page HTML caching with surgical purge: only the pages featuring a changed post refresh, never the whole cache. Images served from the edge URLs rewrite through Cloudflare Image Resizing into right-sized WebP/AVIF variants on the fly. No uploads, no duplicate copies, no migration, no theme changes. The numbers, inside WP admin Free versus managed Free, on your own infrastructure, no account: image URL rewriting through your own Cloudflare zone (native WP filters, srcset, Gutenberg, WooCommerce, the_content and full-page scan), image rules and size mapping, page-cache tag headers with surgical purge to Fastly, Cloudflare Enterprise or your webhook, prewarm on save, coverage audit with a weekly regression email, fake-image detection and repair, purge-failure alerts, a weekly header self-test, a printable client report, the debug overlay, and WP-CLI. Managed, with a Nivoli API key: everything in The Edge Security layer above, the managed page cache and image CDN (no Cloudflare account, plan or DNS work), origin shield, URL rules and the 404 inbox, per-path cache duration, the query-param manager, cache protection, dynamic-content safety for WooCommerce, edge insights and the monthly report, custom image hostname and watermarking, and for agencies a fleet console with one key across sites. Requirements

安装:

  1. Upload the plugin and activate it (or paste your API key on the Managed Edge tab; the managed edge provisions itself and fills the settings in for you).
  2. Free / bring-your-own-zone: open Nivoli Edge → Settings, confirm the auto-detected image host + path prefix, toggle Enabled.
  3. Add rules under Image rules if specific sizes need specific treatment, or let Size mapping create them from your theme's registered sizes in one click. Catch-all handles the rest with zero config.
  4. For HTML caching, open Settings → Page cache and pick a backend (managed Nivoli with your API key, or your own Fastly / CF Enterprise / webhook).
  5. The Dashboard shows whether everything's working and what the edge is doing for you.

屏幕截图:

  • Edge shields: the attack surface strip (XML-RPC, logins, AI crawlers, comment and search floods) and every shield with its switch, enforced before your server.
  • Locks: change lock and install lock, what they refused (by plugin), the wp-admin IP lock and login country lock, and the lock activity log with time and address.
  • Lock activity: what the locks refused in the last 14 days, the exact plugin someone tried to install or update, and the log of who unlocked what, when, from which address.
  • PHP & surface shields: stray PHP and enumeration or leftover requests refused, with off, monitor and block for each.
  • Stats and overview: hour-by-hour traffic, origin offload, hit rates by window, surgical purges.
  • Heaviest images: the files costing the most bandwidth, one-click Tinify shrinking, and what the shrinking has saved so far.
  • Redirects: legacy URLs answered at the edge, patterns and exact rules with usage, unused rules folded away.
  • Recent 404s: paths your server keeps answering with a 404, with bot share and one-click redirect or block.
  • Your audience: humans versus bots, served-from-cache speed, referrers, devices and countries, no tracking script.
  • Static assets: edge hit rate for stylesheets, scripts and fonts, versioned addresses, bandwidth offloaded.
  • Query params: which parameters split the cache, which are guarded, with one-click collapse.

常见问题:

Does this require Cloudflare Pro?

Cloudflare Image Resizing is bundled with Pro plans or available as per-1000-transforms pay-as-you-go. Either is fine.

Will this break my theme?

No. The plugin only modifies URLs at the filter boundary; the HTML structure your theme outputs is unchanged. Use the no-cf CSS class on any element to opt out.

How is this different from Smush / ShortPixel / Optimole?

Those plugins compress and re-host images on their own CDN. Nivoli Edge transforms on the fly from your origin: no asset duplication, no migration step, no storage bill.

What's the difference between Free and Managed?

Everything the plugin does on your own server is free and fully functional: image rewriting, page-cache purging, audits, prewarming, alerts, reports. Nothing phones home. An API key connects the plugin to the Nivoli managed edge: we run the Cloudflare zone and page cache for you (no Cloudflare setup at all) and the service adds what a plugin alone can't, such as edge-side usage statistics, per-URL traffic insights, edge URL rules and security shields, custom hostnames, watermarking, and multi-site fleet management.

What if I lose access to my license email?

Confirmation and unlock links go to the email address on your Nivoli license and nowhere else; that is what makes the locks hold against a takeover. Support can move the license to a new address after verifying you own it. Until then the locks stay as they are and the site keeps running; only changes that weaken protection wait.

Does the install lock break automatic updates?

No. Automatic background updates run from wp-cron on your server and WP-CLI runs on the box; neither passes through the edge, so neither is affected. Only installs, uploads, updates and deletes started from wp-admin are refused, and you open a 15-minute window by email when you want to do one yourself.

What if my site gets hacked anyway?

The locks stop the intruder from switching the shields off, installing anything through WordPress, or redirecting the confirmation address, and every attempt lands in your inbox and on the Locks page with its time and address. What no edge control can do is undo code already running on your server: cleaning the box is still yours (scan, restore, rotate). The locks make sure the compromise stays where it landed.

Does the page caching conflict with my security plugin (Wordfence, Sucuri)?

No. Different layers: security plugins inspect requests inside WordPress/PHP; Nivoli Edge's ten shields run at Cloudflare's edge, before the request reaches your server. It sheds junk traffic so your origin and your security plugin only see real visitors. They complement each other.

Do I need to change my nginx / web-server config?

Only if your origin runs its own micro-cache (nginx fastcgi/proxy cache, Varnish) and you use the manual purge trigger; the Cache protection pane shows the exact one-line snippet. A standard PHP-FPM origin needs no server changes at all.

更新日志:

Recent releases are listed below. The full history for every version is in CHANGELOG.md, which ships with the plugin, and on the GitHub releases page. 1.72.5 When your own Cloudflare zone proxies the domain, Cloudflare holds the certificate until the site's record points at the edge. The check now recognises that answer and unlocks the routing CNAME alongside the validation records, with a callout that says why. 1.72.4 Settings: the pane that puts the site behind the edge is called Managed edge, in the rail and on the card, instead of Page cache. 1.72.3 The routing CNAME stays hidden until the certificate is issued, so it cannot be added too early. On Cloudflare DNS an amber callout says to switch every CNAME to DNS only (proxied, the site never reaches the edge and Cloudflare answers error 1014), and every CNAME card wears a DNS-only pill. 1.72.2 Copy on a DNS record's name copies what the DNS host wants typed: _acme-challenge, _cf-custom-hostname, or @ for the domain itself. The full name stays readable next to it. 1.72.1 The DNS records that put a site behind the edge come as two phases, the same as the guided page: prove ownership and get the certificate first (an ownership TXT and the permanent certificate-delegation CNAME; live traffic untouched), then route traffic (the site's CNAME, unlocked once the certificate is active). One record per card, Copy on name and value, the certificate state remembered between checks. 1.72.0 After the key is activated, an onboarding overview on the account pane and the Dashboard walks the six steps to a site live behind the edge: key, images (test, then switch), pages behind the edge (one click, then the two DNS records inline with copy buttons and a check), shields, locks, the report. Each step shows its state and its button; the card steps aside once the site is live with the locks on. The activation notice is one sentence. 1.71.1 The Security check lives under Tools for every install, Never-loading images under Images. A free install's Managed Edge tab shows Your account only until the site is connected. The own-zone column on the Dashboard is a checked list; each security finding separates what the managed edge does from what to do on the server. 1.71.0 Two free tools. Security check: what this WordPress exposes (XML-RPC, readable usernames, the code editors, missing security headers, version disclosure, readme.html, debug.log, directory listing, a user named admin, HTTPS), five of them fixable from the pane with one click, every finding paired with what the managed edge does about it before PHP. Heaviest uploads: the largest image originals on disk with a one-click Tinify shrink. 1.70.6 The client report is a managed feature now (it is built on edge numbers) and leaves the Tools rail on free installs. The free tools card leads with surgical cache purges for your own CDN and says what they do. 1.70.5 The coverage audit on an install with no image pipeline configured shows a proper empty state with the way forward instead of a Run button that fails with a yellow warning; the fresh Dashboard's tools card no longer offers it. 1.70.4 Free installs get a Tools you can use now card on the Dashboard: never-loading images (posts referencing files that no longer exist), fake images, the coverage audit, size mapping, page-cache purging and the client report, each one click away. They were all there, spread over three tabs. 1.70.3 The own-zone path on the fresh-install Dashboard lists what the free plugin does on your own infrastructure (image rewriting, rules and size mapping, page-cache purging, prewarm, audits, fake-image repair, alerts, client report, WP-CLI) instead of only what it lacks. 1.70.2 A fresh install now opens on one decision: put the site behind the managed edge (three steps: trial, key, two DNS records) or use your own Cloudflare zone for images only. The account pane connects in the same three steps on one card, and the features list is a full-width tile grid. 1.70.1 The free install's Managed Edge pane and the Dashboard checklist now describe what the managed edge is (a security layer above WordPress: shields before PHP, locks a takeover cannot undo, pages and images from the edge, numbers measured there) instead of pitching an image CDN. 1.70.0 Query params: the Dynamic card has an Add a dynamic param field. A filter that exists but has had no traffic yet could not be kept dynamic before, because the only button for it sat on a row in the collapsed list, and a row needs traffic. Type the name, Keep dynamic, done; the edge picks it up within a minute.